Viva Social — Vulnerability Disclosure Policy
Effective: 2026-08-13
If you have found a security vulnerability in Viva Social, we want to hear about it, and we will not take legal action against you for finding it in good faith within the boundaries below.
Reporting
Email support@technologyadvantagesllc.com. Include:
- what the issue is and where it is,
- the steps to reproduce it,
- what an attacker could do with it,
- any proof of concept, ideally as a minimal reproduction.
You may encrypt to the key published at https://vivasocial.online/.well-known/security.txt if you prefer.
What we commit to
| Stage | Target |
|---|---|
| Acknowledgement of your report | 72 hours |
| Initial assessment and severity | 5 business days |
| Fix for a critical issue | 7 days |
| Fix for a high issue | 30 days |
| Fix for medium and low | Next scheduled release |
We will keep you updated, tell you when it is fixed, and credit you publicly if you want the credit. We do not currently run a paid bounty programme.
Safe harbour
If you make a good faith effort to comply with this policy during your research, we will consider your research authorised, we will not pursue or support any legal action against you for it, and we will help make clear that your actions were authorised if a third party raises a complaint.
Scope
In scope
- The Viva Social iOS and Android applications.
- vivasocial.online and its subdomains that we operate.
- Our Supabase edge functions and database, to the extent reachable from a normal client.
Out of scope
- Denial of service, volumetric, or resource exhaustion testing.
- Social engineering of our staff, members, or vendors, including phishing.
- Physical attacks against any person or property.
- Vulnerabilities in third party services we use (Supabase, Stripe, Stream, Mapbox, Twilio, Resend, Sentry, PostHog, OpenTable). Report those to the vendor. If our configuration of one of them is the problem, that is in scope.
- Reports that are output from an automated scanner with no demonstrated impact.
- Missing best-practice headers or TLS configuration with no demonstrated exploit.
Rules
- Do not access, modify, or delete another member's data. Use accounts you control. If you need a second account, create one; do not use a stranger's.
- If you unavoidably encounter personal data belonging to someone else, stop, do not save it, do not share it, and tell us what you saw in your report.
- Do not run tests that degrade the service for members.
- Give us a reasonable opportunity to fix the issue before you publish. We suggest 90 days from acknowledgement, and we will usually be much faster. If you plan to publish, tell us your date.
- Do not extort. A demand for payment in exchange for withholding a report is not a security report.
Things we already know
Please do not report these; they are deliberate design decisions documented in our Privacy Policy:
- Profile pins are snapped to a 500 metre grid with daily jitter, so pin positions are intentionally imprecise and will not match a member's real location.
- Discovery ordering reveals a relative distance ranking that is finer than the coarse distance bands shown in the interface. This is a documented and accepted trade off.
- Profiles that are published are visible to other authenticated members by design, including first name, age, photos, and prompt responses.
Technology Advantages LLC, 28 Valley Road, Montclair, New Jersey 07042, USA · support@technologyadvantagesllc.com